Latest CVE Feed
-
7.2
HIGHCVE-2024-47462
An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote comm... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
6.8
MEDIUMCVE-2024-47464
An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operat... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
4.8
MEDIUMCVE-2024-20534
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (X... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-10081
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints other ... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-20418
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with r... Read more
- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-48746
An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.2
HIGHCVE-2024-47463
An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote comm... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
6.7
MEDIUMCVE-2023-29122
Under certain conditions, access to service libraries is granted to account they should not have access to.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.4
MEDIUMCVE-2024-48312
WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
8.7
HIGHCVE-2024-10082
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root user up until 6... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51115
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
6.6
MEDIUMCVE-2024-34681
Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch.... Read more
Affected Products : android- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-20371
A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should be blocked to the management interface of an affected device. This vulnerabili... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
1.8
LOWCVE-2024-51746
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are returned by the log. gitsign uses Rekor's search API to ... Read more
Affected Products : gitsign- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.4
MEDIUMCVE-2024-10753
A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_two_headers.php. The manipul... Read more
Affected Products : online_shopping_portal- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.1
HIGHCVE-2024-51774
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.... Read more
Affected Products : qbittorrent- Published: Nov. 02, 2024
- Modified: Nov. 06, 2024
-
4.0
MEDIUMCVE-2024-47972
Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-45164
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality ... Read more
Affected Products : secure_internet_access_enterprise_threatavert- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-10751
A vulnerability was found in Codezips ISP Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file pay.php. The manipulation of the argument customer leads to sql injection. The attack may be launc... Read more
Affected Products : isp_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
4.8
MEDIUMCVE-2024-9883
The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : pods- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024